Built to be trusted
TX2Pay is built on enterprise-grade infrastructure with security at every layer. We protect your business data, your clients' payment information, and your operations — so you can focus on growing your business.
Compliance & certifications
Our compliance posture is built on industry standards. We maintain a continuous program rather than treating compliance as a one-time event.
PCI DSS
- Card data is never transmitted to or stored on TX2Pay servers
- All card tokenization handled by Stripe and Usio (PCI Level 1 processors)
- Payment pages use hosted or embedded secure fields
- Annual self-assessment questionnaire (SAQ A) completed
- No cardholder data environment (CDE) on TX2Pay infrastructure
HIPAA Alignment
- TX2Pay does not process Protected Health Information (PHI) as a covered entity
- Security practices align with HIPAA administrative, physical, and technical safeguards
- Data access is role-based and audited
- Encryption at rest and in transit for all data
- Business associates (Supabase, AWS, Stripe) maintain HIPAA-eligible agreements
SOC 2
- Controls mapped to SOC 2 Type II Trust Service Criteria
- Security, Availability, and Confidentiality criteria prioritized
- Audit logging for all data mutations and access events
- Formal SOC 2 Type II engagement planned for Q3 2026
- Penetration testing conducted quarterly
Security controls
Every layer of the TX2Pay stack is secured by design.
Authentication
JWT-based session tokens
Short-lived, cryptographically signed tokens — no persistent sessions stored server-side.
Supabase Auth with MFA support
TOTP-based multi-factor authentication available for all accounts.
Role-based access control
Super-admin, business owner, and staff roles with separate permission scopes.
Data security
Encryption at rest
All database data encrypted at rest using AES-256 on AWS RDS (via Supabase).
TLS 1.2+ in transit
All API traffic and database connections use TLS — no plaintext channels.
Row-Level Security (RLS)
PostgreSQL RLS policies enforce data isolation at the database level — even if application code is bypassed.
Secrets in vault
API keys and sensitive credentials stored in Supabase Vault, not in application config.
Monitoring & audit
Audit logging
All create, update, and delete operations are logged with user ID, IP address, and timestamp.
Rate limiting
Per-IP token-bucket rate limiting on all public endpoints. Graduated tiers: standard, strict, and public.
Edge function logging
All API calls logged with execution time and status. Errors trigger real-time alerts.
Input validation
All incoming data validated with Zod schemas before processing — malformed input is rejected.
Infrastructure
Supabase on AWS
Hosted in AWS us-west-1 (N. California) — SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certified.
Edge functions in Deno
Serverless compute in isolated V8 sandboxes — no shared process memory between tenants.
CDN via Vercel
Frontend served from Vercel's global edge network with automatic HTTPS and DDoS protection.
Backup & recovery
Daily automated backups
Database snapshots taken daily with 30-day retention. Point-in-time recovery available.
Geo-redundant storage
Backups replicated to a secondary AWS region. Data survives regional infrastructure failure.
Tested recovery procedures
Disaster recovery runbooks tested quarterly. RTO target: 4 hours. RPO target: 1 hour.
Incident response
Documented IR plan
Formal incident response plan covering detection, containment, eradication, and recovery phases.
72-hour breach notification
Affected users notified within 72 hours of a confirmed data breach — meeting GDPR and state law requirements.
Security@ contact
Dedicated security contact for vulnerability reports and security inquiries.
Data handling
What we collect, why we collect it, and how long we keep it.
Business data
Account lifetimeBusiness name, address, contact info, logo. Used to power your account and invoices. Retained for the lifetime of your account.
Client data
Account lifetimeClient names, email addresses, phone numbers, and service history. Used to generate invoices and send payment links. You own this data.
Payment records
7 years (tax/legal)Invoice amounts, payment dates, and transaction IDs from payment processors. Raw card numbers are never stored.
Usage analytics
12 monthsAggregated feature usage (no PII). Used to improve the product. No third-party advertising tracking.
Security logs
90 daysIP addresses, timestamps, and action types for audit and incident response. Not shared externally.
Email campaign data
Account lifetimeLead emails, open/click events for campaign analytics. Only for leads you import or create.
Availability commitment
TX2Pay targets 99.9% uptime. Our infrastructure is built on Supabase (AWS) and Vercel, both of which publish their own status pages and uptime SLAs.
99.9%
monthly
Uptime target
4 hrs
after incident
Recovery time objective
1 hr
data loss max
Recovery point objective
Responsible disclosure
If you discover a security vulnerability in TX2Pay, please report it privately. We investigate all reports, aim to respond within 48 hours, and will credit researchers who responsibly disclose issues.
security@tx2pay.comFor general support inquiries, please use our main contact. The security inbox is monitored for vulnerability reports only.

